OSV 1.4.0 · unreviewed · 修改于 2022-01-22 08:01
发布时间
2022-01-15 08:00
GitHub 审查时间
—
NVD 发布时间
2022-01-15 04:15
源文件
advisories/unreviewed/2022/01/GHSA-xhxm-v6fm-53p3/GHSA-xhxm-v6fm-53p3.json
In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be decrypted to obtain the plain-text password.
该公告没有提供结构化的受影响软件包信息。